En del boardingpass mangler digitale signaturer, og de er lette å manipulere. Dette utgjør et stort stikkerhetshull på flyplasser, skriver Washington Post.
Vissheten om sikkerhetshullet har vært der en god stund, at det ikke er tettet skyldes ikke teknologi, men policy.
10.000 mennsker står på en no-fly-liste inn til USA. I tillegg kommer et høyere antall som må ha sikkerhetsklarering to ganger. Det er noen av disse man frykter kan komme til å manipulere boardingpass for å komme seg om bord.
The security gaps center on airline boarding passes, which can be issued up to 24 hours before a flight’s departure. According to security researchers, the bar codes on those passes can be manipulated with widely available technology to change the information they contain: passenger identification, flight data, and codes indicating whether a passenger has qualified for expedited screening.
Information about reading and altering boarding pass bar codes has circulated on online forums for several months, and has recently been picked up by security researchers. Many of them note that the potential for tampering with the passes has been exacerbated by the proliferation of smartphones that can read the bar codes and free software that can manipulate them.
Security guidelines set by the Transport Security Administration allow airlines to add an encrypted “digital signature” to prevent board passes from being altered. But some experts said they were surprised to learn that not all passes include authentication.
“It’s alarming — this basically negates the no-fly list,” said Chris Soghoian, a fellow at Indiana University’s Center for Applied Cybersecurity Research and principal technologist at the American Civil Liberties Union.
It remains difficult to establish the full extent of the vulnerabilities without information from the TSA, which does not comment on security procedures.
In response to written questions, John S. Pistole, the administrator of the TSA, said that the potential for tampering with printed boarding passes has existed since the inception of e-ticketing but that the agency has added protective measures “both seen and unseen.”
“We continue to explore and implement additional mitigation measures to prevent the manipulation of boarding passes and are working with the airlines to develop systems and methods to prevent illegal tampering,” Pistole said.